Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,699
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 801 - 820 of 35,345 CVEs

A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local fil...

Vendor: maven
Product: com.linecorp.armeria:armeria-xds
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54683 MEDIUM - 6.5

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

Vendor: maven
Product: nl.nl-portal:documenten-api
Published: Jun 18, 2026
Source: GitHub
CVE-2026-54319 MEDIUM - 4.2

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.186, a sandbox volume reference (volumeId, which may also be a volume name) was forwarded to the runner and used to build the host bind-mount source path without confinement. A refe...

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 18, 2026
Source: GitHub
CVE-2026-56024 MEDIUM - 6.5

Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue affects WP EasyPay: from n/a through 4.4.0.

Vendor: Saad Iqbal
Product: WP EasyPay
Published: Jun 18, 2026
Source: NVD
CVE-2026-56022 MEDIUM - 5.3

Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, allowing bypass of additional MFA requirements. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56021 MEDIUM - 5.3

Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due to a bypassable regex pattern.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-56020 HIGH - 8.1

The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL client certificate by sending a forged HTTP header. A remote attacker can spoof certificate DNs and authenticate as any user. Fixed in 2.641.

Vendor: Webmin
Product: Webmin
Published: Jun 18, 2026
Source: NVD
CVE-2026-55237 HIGH - 8.8

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions prior to 0.6.62 have a DOM-based Cross-Site Scripting (XSS) vulnerability in AutoGPT's signup page. The application improperly trusts a URL parameter (`next`), whi...

Vendor: Significant-Gravitas
Product: AutoGPT
Published: Jun 18, 2026
Source: NVD
CVE-2026-55205 MEDIUM - 5.3

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust server memory and th...

Vendor: nesquena
Product: hermes-webui
Published: Jun 18, 2026
Source: NVD
CVE-2026-55204 HIGH - 7.5

HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions unde...

Vendor: haproxy
Product: haproxy
Published: Jun 18, 2026
Source: NVD
CVE-2026-55203 HIGH - 7.5

HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect recor...

Vendor: haproxy
Product: haproxy
Published: Jun 18, 2026
Source: NVD
CVE-2026-54106 MEDIUM - 4.7

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) do not validate X-Forwarded-For HTTP headers, allowing a remote attacker with compromised administrator credentials to bypass net...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54105 MEDIUM - 5.3

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) expose sensitive account information through the 'update-profile/' API endpoint. A remote, unauthenticated attacker can...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54104 HIGH - 8.8

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) trusts client-provided values for the 'epds_role_id' parameter without verification, allowing a remote, authenticated a...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD
CVE-2026-54103 CRITICAL - 9.8

The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attac...

Vendor: Government Accountability Office, Civilian Board of Contract Appeals
Product: Electronic Protest Docketing System (EPDS), Electronic Docketing System (EDS)
Published: Jun 18, 2026
Source: NVD

A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22*...

Vendor: nodejs
Product: node
Published: Jun 18, 2026
Source: NVD
CVE-2026-38718 HIGH - 7.5

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerability in the device registration function. This vulnerability could allow an attacker to cause a denial of service attack on the remote target device.

Vendor: inhandnetworks
Product: ir915l-fq39-s_firmware
Published: Jun 18, 2026
Source: NVD
CVE-2026-38717 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Vendor: inhandnetworks
Product: ir915l-fq39-s_firmware
Published: Jun 18, 2026
Source: NVD
CVE-2026-38716 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Vendor: inhandnetworks
Product: ir915l-fq39-s_firmware
Published: Jun 18, 2026
Source: NVD
CVE-2026-38715 CRITICAL - 9.8

InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.

Vendor: inhandnetworks
Product: ir915l-fq39-s_firmware
Published: Jun 18, 2026
Source: NVD